[Snort-users] stealth mode and openbsd 3.3

Erek Adams erek at ...950...
Tue May 27 08:46:09 EDT 2003


On Fri, 23 May 2003, Bert Beaudin wrote:

> Currently attempting to run snort in stealth mode on openbsd 3.3. Snort
> 2.0.0 built from source. I have the interface sis0 up.
>
>
> sis0: flags=8943<UP,BROADCAST,RUNNING,PROMISC,SIMPLEX,MULTICAST> mtu
> 1500
>         address: 00:09:5b:06:63:f8
>         media: Ethernet autoselect (100baseTX full-duplex)
>         status: active
>         inet6 fe80::209:5bff:fe06:63f8%sis0 prefixlen 64 scopeid 0x2

[...snip...]

> rl0: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> mtu 1500
>         address: 00:30:84:3e:69:8d
>         media: Ethernet autoselect (100baseTX full-duplex)
>         status: active
>         inet 192.168.20.13 netmask 0xffffff00 broadcast 192.168.20.255
>         inet6 fe80::230:84ff:fe3e:698d%rl0 prefixlen 64 scopeid 0x1

[...snip...]

> What am I doing wrong? Any help would be great.
> PS both interfaces are attacahed to the same hub.

Snort is IPv4 only.

-----
Erek Adams

   "When things get weird, the weird turn pro."   H.S. Thompson




More information about the Snort-users mailing list